check / check (push) Successful in 3m23s
upaas uploads its clone as a tar context, which .dockerignore does not filter, so its builds already carried .git; the unknown default of the VERSION build arg is what stamped them. The image now derives its version itself: ARG VERSION has no default, so make build falls back to script/version, which runs git describe on the copied .git; a VERSION build arg still wins. .dockerignore sends .git without its config in a directory context and no longer leaves out tracked files, which would mark the tree -dirty. The builder installs git, trusts /build as a safe.directory, and fails when .git is present but the version comes out unknown. A shallow single-branch clone stamps its short commit. Model: opus-5-5
28 lines
886 B
Plaintext
28 lines
886 B
Plaintext
# .git is sent so the build can derive the version it stamps into the binary
|
|
# (script/version). Its config, which can hold a remote URL carrying a
|
|
# credential and which `git describe` does not need, is left out of a
|
|
# directory context. A context sent as a tar is not filtered by this file, so
|
|
# it carries .git/config unless its sender leaves it out.
|
|
.git/config
|
|
|
|
# No tracked file may be listed here: git in the build would see it as
|
|
# deleted and mark the version -dirty.
|
|
#
|
|
# .ci-fingerprint is deliberately NOT excluded: it is the CI cache barrier
|
|
# that keeps the check stages from replaying a cached pass. See the lint
|
|
# stage of the Dockerfile.
|
|
bin/
|
|
# Extracted from 3p/ by `make assets` inside the build; a host copy is not
|
|
# needed. The tarball in 3p/ must stay in the context.
|
|
static/js/alpine.min.js
|
|
.env
|
|
.env.*
|
|
*.db
|
|
*.sqlite
|
|
*.sqlite3
|
|
.DS_Store
|
|
.idea/
|
|
.vscode/
|
|
tmp/
|
|
temp/
|